SYSTEM AND METHOD FOR MODELING ACTIVITY PATTERNS OF NETWORK TRAFFIC TO DETECT BOTNETS

Number of patents in Portfolio can not be more than 2000

United States of America Patent

APP PUB NO 20110153811A1
SERIAL NO

12821510

Stats

ATTORNEY / AGENT: (SPONSORED)

Importance

Loading Importance Indicators... loading....

Abstract

See full text

The invention relates to a system and method that can detect botnets by classifying the communication activities for each client according to destination or based on similarity between the groups of collected traffic. According to certain aspects of the invention, the communication activities for each client can be classified to model network activity by differentiating the protocols of the collected network traffic based on destination and patterning the subgroups for the respective protocols. Those servers that are estimated to be C&C servers can be classified into download and upload, spam servers and command control servers, within a botnet group detected by modeling network activity, i.e. analyzing network-based activity patterns. Also, botnet groups can be detected by way of a group information management function, for generating an activity pattern-based group matrix based on group data, and a mutual similarity analysis, performed on groups suspected to be botnets from the group information.

Loading the Abstract Image... loading....

First Claim

See full text

Family

Loading Family data... loading....

Patent Owner(s)

Patent OwnerAddress
KOREA INTERNET & SECURITY AGENCY9 JINHEUNG-GIL NAJU-SI JEOLLANAM-DO 58324

International Classification(s)

  • [Classification Symbol]
  • [Patents Count]

Inventor(s)

Inventor Name Address # of filed Patents Total Citations
IM, Chae Tae Seoul, KR 13 395
Jeong, Hyun Cheol Seoul, KR 40 1460
Ji, Seung Gao Gyeonggi-do, KR 1 140
Kang, Dong Wan Seoul, KR 9 245
Lee, Tae Jin Seoul, KR 255 1420
Oh, Joo Hyung Seoul, KR 9 369
Won, Yong Geun Seoul, KR 6 184

Cited Art Landscape

Load Citation

Patent Citation Ranking

Forward Cite Landscape

Load Citation